Webhook Path Route Replacement Vulnerability in OpenClaw's Synology Chat Extension
CVE-2026-35635
6.3MEDIUM
What is CVE-2026-35635?
The Synology Chat extension in OpenClaw prior to version 2026.3.22 is susceptible to a webhook path route replacement vulnerability. This flaw allows attackers to exploit multi-account configurations by collapsing them onto shared webhook paths, thereby bypassing account-specific access control policies. As a result, they can manipulate route ownership across different accounts, posing a significant risk to user data and privacy. It is imperative for users to upgrade to the latest version to mitigate this security risk.
Affected Version(s)
OpenClaw 0 < 2026.3.22
OpenClaw 2026.3.22
